Toot

Written by Ludovic Courtès on 2024-10-02 at 20:31

@goblin On Linux, a more limited form of sandboxing is provided through namespaces (CLONE_NEWNS, unshare, etc.), and that can be used by systemd to isolate services that do not themselves use sandboxing directly:

https://0pointer.de/blog/projects/security.html

Likewise for the Shepherd:

https://guix.gnu.org/en/blog/2017/running-system-services-in-containers/

I suspect the study slightly underestimates use of sandboxing on Linux. WDYT?

=> More informations about this toot | View the thread | More toots from civodul@toot.aquilenet.fr

Mentions

=> View goblin@crispsandwi.ch profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113239727937707291
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
233.894986 milliseconds
Gemini-to-HTML Time
0.35399 milliseconds

This content has been proxied by September (3851b).